PT-2025-50274 · Freepbx · Freepbx Endpoint Manager

CVE-2025-66039

·

Published

2025-12-09

·

Updated

2026-04-01

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: FreePBX Endpoint Manager versions 16.0.0 through 16.0.43 and 17.0.0 through 17.0.22.
Description: FreePBX Endpoint Manager is susceptible to an authentication bypass when the authentication type is configured to 'webserver'. An attacker can forge an Authorization header with a valid username and any password, gaining unauthorized access. The system incorrectly verifies incoming requests when the 'webserver' authentication type is selected, blindly trusting the Authorization: Basic header. This allows an attacker to associate a session with a target user without valid credentials. Exploitation can lead to SQL injection and remote code execution when chained with other flaws.
Recommendations: Update the Endpoint Manager module to versions 16.0.44 or 17.0.23 or higher. As a temporary measure, disable the 'webserver' authentication type if it is not required.

Exploit

Fix

RCE

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-15989
CVE-2025-66039
GHSA-9JVH-MV6X-W698

Affected Products

Freepbx Endpoint Manager